4 ms·
Adversarially generated inputs have been known for some time [1], so I wouldn’t call it a new class of attacks unless 1. there are other and older ways of attac
by QML 8y ago
Adversarially generated inputs have been known for some time [1], so I wouldn’t call it a new class of attacks unless 1. there are other and older ways of attacking neural networks 2. new as in the last couple of years.
[1] https://blog.openai.com/adversarial-example-research/ https://blog.openai.com/adversarial-example-research/
- p1esk 8y agoYes, this can be used for generating adversarial inputs, and yes, this is a new attack surface. From the paper: The images generated here could be viewed as a variant of adversarial examples, in which small image perturbations (imperceptible to humans) cause a large shift in the network’s output. The images we generate are of a somewhat opposite flavor: while we do not limit the magnitude of the difference between the original and modified image, the detectors are sometimes “blind” to the inserted object. In addition, our examples are not “targeted” in the sense that no optimization process is required to generate them; they seem prevalent enough so that a simple scan of transplanting translated versions of one object in the other can give rise to multiple wrong interpretations.